Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- Why does a missing Content - Security - Policy header matter?
- How do I add a Content - Security - Policy header on my server?
- Should I start with Report - Only mode?
- How can I build a baseline enforcing policy?
- What should I do about inline scripts and styles?
- How do I verify that the CSP header is correctly deployed?
- What next after the header is working?
- How does Decloak help fix CSP issues?
Key takeaways
- Add the CSP header in your server, reverse - proxy, or framework configuration.
- Deploy a Report - Only header first to collect violation data without breaking the site.
- Refine the policy iteratively, moving from a permissive baseline to a strict enforcing header.
- Replace inline code with nonces or hashes, or use
'unsafe - inline'only when absolutely required. - Verify the header with curl, browser dev tools, or an online scanner before considering the issue resolved.
Why does a missing Content - Security - Policy header matter?
A missing CSP header leaves the browser without guidance on which resources are allowed, making it easy for attackers to inject malicious scripts. Adding CSP blocks many cross - site scripting attacks and reduces the impact of content injection flaws.
How do I add a Content - Security - Policy header on my server?
Configure your web server, reverse - proxy, or application framework to send the header in every response. For Nginx use add_header Content - Security - Policy "...";. For Apache add Header always set Content - Security - Policy "..." in .htaccess or the VirtualHost. Frameworks such as Express can use Helmet, Django can use django - csp, and Flask can use Flask - Talisman.
Should I start with Report - Only mode?
Yes. Deploy Content - Security - Policy - Report - Only first so browsers report violations without blocking content. Example header:
Content - Security - Policy - Report - Only: default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self'; font-src 'self'; connect-src 'self'; frame-ancestors 'none'; report-uri /csp-violations
Collect reports for a few days, then use the data to tighten the enforcing policy.
How can I build a baseline enforcing policy?
Start with a permissive but explicit baseline and add sources only as needed. A common starting point:
Content - Security - Policy: default-src 'self';
script-src 'self' https://cdn.example.com https://www.google-analytics.com;
style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;
img-src 'self' data: https:;
font-src 'self' https://fonts.gstatic.com;
connect-src 'self' https://api.example.com https://www.google-analytics.com;
frame-ancestors 'self';
base-uri 'self';
form-action 'self';
upgrade-insecure-requests
Adjust each directive based on the violation reports you gathered.
What should I do about inline scripts and styles?
Replace inline code with nonces or hashes. Generate a unique nonce per response and add it to the CSP header, e.g., script-src 'self' 'nonce-<random>'. If replacement is impossible, limit 'unsafe-inline' to the specific directives that need it and keep it off everywhere else.
How do I verify that the CSP header is correctly deployed?
Run a simple curl command and look for the header:
curl -sI https://example.com | grep -i "content-security-policy"
Check the browser developer tools console for CSP warnings or violations. Optionally run an online scanner such as Decloak's free scan to confirm the header appears and that no CSP - related findings remain.
What next after the header is working?
Monitor the report - only logs for a week to ensure no legitimate content is blocked. Then remove the Report - Only header and keep the enforcing CSP. Periodically re - run scans, especially after adding new third - party scripts or changing the site architecture.
How does Decloak help fix CSP issues?
Decloak's free scan checks the HTTP/TLS posture layer and reports a missing CSP header as a finding. The scan also shows the current header value (if present) and provides a graded recommendation, helping you confirm that your fix resolves the issue.
Related guides
Is HTTP 1.1 a security risk?
HTTP 1.1 is not a direct vulnerability, but its plain - text design and parsing ambiguities can create attack surfaces that need mitigation, especially when not used over TLS.
Is JavaScript a security risk?
JavaScript can be a major attack surface because injected scripts run with the same privileges as the page, but proper sanitization, CSP, and safe frameworks eliminate most risks.
What is cross - site scripting (XSS) and how to prevent it
Cross - site scripting (XSS) lets attackers run malicious code in a victim’s browser by injecting untrusted data into web pages. Learn the three XSS types, how they work, and concrete steps to protect your site.